Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities

Mistic backdoor linked to ransomware access broker KongTuke

A newly identified backdoor, Mistic, is being used by the KongTuke access broker to facilitate ransomware attacks on corporate networks.

Mistic backdoor linked to ransomware access broker KongTuke
Clay Banks · Unsplash

Security firms Symantec and Zscaler have uncovered a new backdoor malware, dubbed Mistic, which is being deployed by the KongTuke initial access broker (IAB) to compromise corporate networks. KongTuke, active since at least 2024, specializes in breaching organizations and selling that access to ransomware operators, including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The discovery highlights the growing sophistication of tools used by access brokers to maintain stealth and persistence in targeted environments.

How Mistic operates

Mistic is designed for long-term, low-visibility access to compromised systems. According to Symantec, the malware is typically side-loaded via a legitimate executable, MpExtMs.exe, which loads a malicious DLL (version.dll) that subsequently deploys Mistic under the guise of a Microsoft endpoint security tool (EndpointDlp.dll). This naming convention is likely intended to evade suspicion by blending in with legitimate software.

Once active, Mistic communicates with its command-and-control (C2) infrastructure and can execute a range of commands, including file manipulation, in-memory code execution, and self-termination. Zscaler, which tracks the malware as MTLBackdoor, notes that one of its most potent features is the ability to load Beacon Object Files (BOFs)—small, in-memory programs that expand its capabilities without writing to disk. This technique is commonly associated with red teaming tools like Cobalt Strike and is increasingly used in post-exploitation attacks to avoid detection by security agents.

Background

Background: Initial access brokers (IABs) are cybercriminals who specialize in breaching corporate networks and selling that access to other threat actors, such as ransomware groups. Their tools and techniques often prioritize stealth and persistence to maximize the value of the compromised access.

The infection chain often begins with social engineering attacks, such as those delivered via Microsoft Teams. In at least one documented case, Mistic was deployed shortly after ModeloRAT, another backdoor attributed to KongTuke. The group has also been observed using other tools, including WinPython and Node.js runtimes to execute malicious code, the finger.exe utility to retrieve obfuscated payloads, and malware loaders like MintsLoader and D3F@ck Loader.

Why the discovery matters

The emergence of Mistic underscores the evolving tactics of ransomware-affiliated access brokers. Unlike off-the-shelf malware, custom tools like Mistic are tailored to evade detection and maintain persistence, making them particularly dangerous for organizations with mature security postures. Symantec’s researchers emphasize that the backdoor’s in-memory execution and self-deletion capabilities are hallmarks of an operator seeking long-term, undetected access.

KongTuke’s use of multiple tools and techniques further complicates detection efforts. For example, the group has previously employed ClickFix and its variants (FileFix and CrashFix) to deliver ModeloRAT, as well as fake browser extensions like NexShield and encrypted payloads such as GateKeeper. This multi-tool approach allows the group to adapt to different security environments and evade signature-based defenses.

For professionals

For professionals: Organizations should prioritize monitoring for unusual process execution, particularly side-loading of legitimate executables with malicious DLLs. In-memory payload execution, such as BOFs, is a red flag for advanced threats like Mistic. Regular breach and attack simulation (BAS) testing can help identify gaps in detection rules for SIEM and EDR systems.

What to watch

The discovery of Mistic suggests that KongTuke is investing in custom malware development to enhance its access brokerage services. Security teams should expect similar tools to emerge as IABs seek to differentiate themselves in a competitive ransomware ecosystem. Additionally, the use of BOFs and other in-memory techniques may become more prevalent as attackers refine their evasion tactics.

Symantec and Zscaler have released indicators of compromise (IoCs) for Mistic/MTLBackdoor, which organizations can use to hunt for signs of infection. Given KongTuke’s history of targeting sectors like insurance, education, IT, and professional services, companies in these industries should be particularly vigilant.

Companies mentioned

KongTuke Broadcom Zscaler

Discussion · coming soon

Be the first to join the thread when community discussion launches.